The U.S. National Institute of Standards and Technology (NIST) has finalized and published a new report providing comprehensive guidelines on securing digital identity and access tokens. The release on September 15, 2026, is a direct response to recent high-profile breaches where threat actors used stolen cryptographic signing keys to forge access tokens and infiltrate sensitive government networks, such as the theft of 60,000 emails from a U.S. agency. The guidance is designed to help both Cloud Service Providers (CSPs) and their customers, particularly federal agencies, strengthen their defenses against token theft and misuse. The final document incorporates industry feedback and includes forward-looking considerations for AI security and post-quantum cryptography.
The publication, a result of collaboration through the Joint Cyber Defense Collaborative, establishes a set of security principles for the entire lifecycle of access tokens. It addresses the generation, storage, usage, and revocation of these critical assets. The guidance was prompted by incidents where attackers, having obtained a single cryptographic key, were able to mint their own valid tokens, granting them broad access to cloud environments like Microsoft Exchange Online.
Key changes from the draft version (released in December 2025) include:
The guidance is broadly applicable but is primarily targeted at:
While the NIST document is a guideline and not a regulation, it establishes a new baseline of best practices that will likely influence future compliance frameworks and federal contracts. Organizations should review their identity and access management (IAM) strategies against these principles. Key areas of focus include:
The publication of this guidance will likely drive significant investment and architectural changes in how organizations manage identity. For cloud customers, it will necessitate a deeper understanding of their CSP's identity architecture and a more active role in securing their side of the shared responsibility model. For CSPs, it will increase pressure to provide more transparent and robust security controls around their identity infrastructure. The long-term impact will be a more resilient identity ecosystem that is harder for attackers to compromise through token-based attacks.
Organizations should take the following steps to align with the new NIST guidance:
The entire guidance document is focused on protecting credentials, specifically access tokens.
Strong authentication is a foundational principle for protecting initial access before a token is even issued.
Mapped D3FEND Techniques:
NIST releases a draft version of the token protection guidelines for public comment.
NIST publishes the finalized report on securing digital identity and access tokens.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.